DevSecOps Engineer - Leesburg

Fortreum•Leesburg, VA
•$155,000 - $205,000•Onsite

About The Position

Fortreum is a leader in cloud and cybersecurity services, ranked among the Top 5 FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, Fortreum has expanded its capabilities to include advanced cyber risk quantification and analytics. The company delivers independent, third-party, vendor-agnostic regulatory assessment and advisory services, alongside advanced cybersecurity offensive and compliance technical solutions. Fortreum's service portfolio spans regulatory compliance frameworks including FedRAMP, CMMC, FISMA, SOC, PCI, ISO, and HIPAA. Fortreum is transforming compliance through the Kovr AI Platform, an AI-native compliance automation solution. The Kovr AI Platform applies intelligent, autonomous workflows to the assessment and authorization lifecycle, automating artifact generation, evidence and control mapping, and continuous validation across various frameworks. This role offers the opportunity to work with industry-leading experts and support security-conscious organizations. As a DevSecOps Engineer, you will embed with enterprise and federal customers to deploy, integrate, and operationalize the Kovr AI Platform within their environments. This includes building integrations with their DevSecOps toolchains, automating evidence collection and continuous monitoring, and configuring compliance workflows to accelerate Authority to Operate (ATO). You will act as the technical bridge between customers and Fortreum's engineering team, addressing complex deployment challenges across cloud, hybrid, and classified National Security and Intelligence Community (IC) environments.

Requirements

  • 7+ years of DevOps, Platform Engineering, or Site Reliability Engineering experience
  • Hands-on experience architecting AWS infrastructure using Terraform at scale
  • Strong production experience with Kubernetes (EKS or similar), including cluster design, Helm Charts, and GitHub/GitOps workflows
  • Direct experience with FedRAMP, CMMC, NIST 800-53/800-171, or DoD SRG compliance environments
  • Familiarity with OSCAL or other machine-readable compliance/documentation frameworks
  • Experience integrating SAST/DAST or IaC security scanning into a pipeline
  • Scripting/automation proficiency (Python, Bash, or similar)
  • U.S. Citizenship, with the ability to obtain and maintain a Top Secret clearance, due to contractual requirements
  • Comfortable working in a fast-moving startup-within-a-company environment
  • Local to Washington, DC metro area

Nice To Haves

  • Existing security or cloud certifications (Security+, AWS Certified Security, CYSA+, CISSP)
  • Experience integrating LLM coding agents, MCPs, and automations into DevOps workflows
  • Background supporting federal DevSecOps deployments or highly regulated commercial clients

Responsibilities

  • Design, build, and maintain CI/CD pipelines supporting rapid, secure software delivery
  • Manage cloud infrastructure (AWS, with exposure to Azure/GCP) using Infrastructure as Code (Terraform), including module design and reusable patterns for the broader team
  • Administer and scale containerized workloads (Kubernetes/EKS, Helm, ArgoCD)
  • Implement and maintain security controls and monitoring aligned to NIST 800-53 and OSCAL-based frameworks
  • Design observability strategy (logging, metrics, alerting, SLOs) to support production reliability at scale
  • Integrate DevOps tooling (GitHub, JIRA, Splunk, Snyk) into automated compliance and remediation workflows
  • Collaborate with existing engineering and compliance teams to ensure infrastructure changes maintain continuous authorization posture
  • Support continuous monitoring and audit-readiness activities, including evidence collection and control mapping
  • Troubleshoot production issues and drive continuous improvement in deployment reliability
  • Build and maintain documentation, runbooks, and architecture decision records
  • Represent infrastructure/security in cross-functional planning, including customer-facing technical conversations when needed

Benefits

  • medical insurance
  • dental insurance
  • vision insurance
  • 401K plan with a 4% match
  • company paid short-term disability
  • company paid long-term disability
  • company paid AD&D and life insurance
  • flex time off
  • annual bonuses
  • training stipends
  • certification reimbursements
  • access to over 30,000 free online training courses
  • personal cell phone allowance
  • new hire and annual home office stipend
  • spot awards
  • eleven paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service